New npm worm hits CI pipelines and AI coding tools

A massive Shai-Hulud-style npm supply chain worm is hitting the software ecosystem, burrowing through developer machines, CI pipelines, and AI coding tools. Socket researchers uncovered the active attack campaign and called it SANDWORM_MODE,  derived from the “SANDWORM_*” environment variable switches embedded in the malware’s runtime control logic.” At least 19 typosquatted packages were published under multiple aliases, posing…

Read More

Three web security blind spots in mobile DevSecOps pipelines

We know that mobile development in 2025 was different. It shifted from a “front-end” concern to a massive, distributed headache in which the most vulnerable component could be any unmanaged, hostile endpoint. In fact, 43% of organizational breaches originate at the mobile edge. The problem lies with the outdated web-centric security models that app developers…

Read More

AWS adds Advanced Prompt Optimization tool to Bedrock

AWS late on Thursday added a new prompt optimization tool to Amazon Bedrock, its fully managed service for building, deploying, and scaling generative AI applications. The tool, Amazon Bedrock Advanced Prompt Optimization, can be accessed through the Bedrock console, and is designed to automatically refine prompts for better accuracy, consistency, and efficiency across multiple large…

Read More

First look: Lemonade serves up local AI with limitations

Lemonade, created by AMD, is a server application plus GUI for running local AI models, similar to projects like LM Studio (or, more distantly, ComfyUI). What it lacks in configurability, it tries to make up for in broader integration with third-party apps that use standard APIs, and with support for non-NVIDIA runtimes. Lemonade works with…

Read More

Measure The Business Value Of Data And Analytics Investments

To advance data‑driven transformation, enterprises need structured approaches that clearly link analytics initiatives to business outcomes and communicate impact consistently. Yet most enterprises still lack mature, repeatable practices for measuring and communicating the value of enterprise investments in data and analytics. That leaves the business impact of these investments unclear. And because direct causation is…

Read More

New Study Shows How to Close the AI Readiness Gap With Trusted Data and Talent

A recent report from Precisely highlights an interesting paradox: 87% of organizations believe they are ready for AI, yet at the same time, 40% of the leaders reported that data, skills, and infrastructure remain the biggest obstacles. Precisely’s fourth annual State of Data Integrity and AI Readiness report reveals a growing disconnect in how organizations…

Read More